M
Cyber Security Auditor- Hybrid Aberdeen, MD
Salary undisclosed
Apply on
Original
Simplified
Cyber Security Auditor
The company is located in Aberdeen, MD and will require 2-3 days onsite a week.
What You Will Be Doing:
This position doesn't provide sponsorship.
The company is located in Aberdeen, MD and will require 2-3 days onsite a week.
What You Will Be Doing:
- Use HP Fortify to analyze code scan results submitted by developers
- Identify and validate false positives in scan results
- Provide comments on vulnerabilities identified and recommend POA&M (Plan of Action and Milestones) mitigations
- Install software on isolated VMs and evaluate it against 800-53 controls and AS&D STIG
- Use tools like Wireshark and Attack Surface Analyzer to assess software traffic and connections
- Assess hardware compliance with designated STIG or SRG requirements
- Document assessment findings and suggest mitigation strategies
- Support assessments of subordinate sites for compliance with STIG, 800-53 controls, and Army regulations
- Conduct STIG checklist reviews for branch-managed packages
- Perform technical control audits in eMASS
- Bachelor's degree in a relevant field with at least 5 years of experience; equivalent experience may substitute for a degree
- Required certification in one of the following: CSSP-AU, CISA, IASAE, CASP+CE, CISSP (or associate), CSSLP
- Must meet DoD 8570.01-M requirements for IAT Level II or IAM Level I
- Relevant education and/or experience in the program area (Computer Science, Software Engineering, Information Systems), with specialized expertise in cybersecurity or information assurance
- Specialized experience in AS&D STIG compliance, secure software development and testing, static and dynamic code analysis, software assurance, threat modeling, software/hardware risk and vulnerability analysis, or related functions
- Proficiency with cybersecurity and IT audit tools such as ACAS, HP Fortify, HP Web Inspect, BURP Suite, and other software assurance tools
- Must be able to obtain and maintain a Secret clearance
This position doesn't provide sponsorship.
Employers have access to artificial intelligence language tools (“AI”) that help generate and enhance job descriptions and AI may have been used to create this description. The position description has been reviewed for accuracy and Dice believes it to correctly reflect the job opportunity.
Report this job Similar Jobs